Amazon Product Scraper

Security checks across malware telemetry and agentic risk

Overview

This skill does what it says: it browses Amazon product pages the user provides and saves a local competitor-analysis report.

Install only if you are comfortable with the agent browsing Amazon product pages you provide and keeping the generated report in local memory. Delete saved reports you no longer need, and avoid using it for scraping patterns that could violate Amazon’s terms or rate limits.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill instructs the agent to save a generated report into a local memory file but does not clearly warn the user or obtain consent before persisting scraped content. Hidden persistence can surprise users, retain potentially sensitive browsing-derived data longer than expected, and create secondary exposure if other skills or sessions can access memory files.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal